The phpMyAdmin development team reports:
XSRF/CSRF vulnerability in phpMyAdmin setup.
By deceiving a user to click on a crafted URL, it is
possible to alter the configuration file being generated
with phpMyAdmin setup.
This vulnerability only affects the configuration file
generation process and does not affect the effective
configuration file. Moreover, the configuration file being
generated is at risk only during the period when it's
writable.
Vulnerability allowing man-in-the-middle attack on API
call to GitHub.
A vulnerability in the API call to GitHub can be
exploited to perform a man-in-the-middle attack.
We consider this vulnerability to be serious.